A Network Activity Classification Schema and Its Application to Scan Detection

A Network Activity Classification Schema and Its Application to Scan Detection
复制标题

DOI:
10.1109/tnet.2011.2109009
复制
发表时间:
2011-10
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
J. Treurniet
J. Treurniet
中科院分区:
其他
文献类型:
--
作者:
J. Treurniet

文献摘要

被引文献

相似文献

互联网流量既没有良好的行为,也没有被很好地理解,这使得检测诸如扫描之类的恶意活动变得困难。扫描活动的很大一部分是慢扫描类型,目前无法被安全设备检测到。在这个概念验证研究中,我们展示了一种新的扫描检测技术,它也提高了我们对互联网流量的理解。会话是使用主机对之间包级数据的行为模型创建的,活动是通过基于会话类型、IP地址和端口中的模式对会话进行分组来标识的。在24小时内近1000万个传入会话的数据集中,惊人的78%被识别为扫描探针。80%的扫描比基本检测方法所能识别的慢。为了管理大量扫描,引入了一种优先排序方法,其中扫描根据是否做出响应和扫描中探针的周期性进行排序。数据以有效的方式存储,允许活动信息保留很长一段时间。该技术通过对已知活动进行分类来深入了解Internet流量,通过扫描检测对网络威胁提供可见性,同时还扩展了对网络上发生的活动的感知。
Internet traffic is neither well-behaved nor well-understood, which makes it difficult to detect malicious activities such as scanning. A large portion of scanning activity is of a slow scan type and is not currently detectable by security appliances. In this proof-of-concept study, a new scan detection technique is demonstrated that also improves our understanding of Internet traffic. Sessions are created using models of the behavior of packet-level data between host pairs, and activities are identified by grouping sessions based on patterns in the type of session, the IP addresses, and the ports. In a 24-h data set of nearly 10 million incoming sessions, a prodigious 78% were identified as scan probes. Of the scans, 80% were slower than basic detection methods can identify. To manage the large volume of scans, a prioritization method is introduced wherein scans are ranked based on whether a response was made and on the periodicity of the probes in the scan. The data is stored in an efficient manner, allowing activity information to be retained for very long periods of time. This technique provides insight into Internet traffic by classifying known activities, giving visibility to threats to the network through scan detection, while also extending awareness of the activities occurring on the network.